{"_id":"@attestry/mcp-server","name":"@attestry/mcp-server","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@attestry/mcp-server","version":"1.0.0","description":"MCP server for Attestry — the cryptographically-verifiable AI compliance platform","license":"MIT","author":{"name":"Attestry"},"homepage":"https://attestry.ai","bugs":{"email":"support@attestry.ai"},"keywords":["mcp","model-context-protocol","ai-compliance","eu-ai-act","colorado-ai-act","nist-ai-rmf","iso-42001","attestry","compliance","claude"],"type":"module","main":"dist/index.js","bin":{"attestry-mcp":"dist/index.js"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc","dev":"tsc --watch","start":"node dist/index.js","prepare":"npm run build","prepublishOnly":"npm run build"},"dependencies":{"@modelcontextprotocol/sdk":"^1.27.1","zod":"^3.24.2"},"devDependencies":{"@types/node":"^22.0.0","typescript":"^5.7.0"},"engines":{"node":">=18.0.0"},"gitHead":"461ccccc1f9ca273bbe988cb4e962e7079070784","types":"./dist/index.d.ts","_id":"@attestry/mcp-server@1.0.0","_nodeVersion":"24.13.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-laWfLzHums76L4tkZCRDpXPgpPl9B9QqvScHIDBJE05+RDgoHdRy/IxPxPjirOG63Cj+sfD5pDnBbLDWygQOqQ==","shasum":"ccc0ae5a54393c26085fe2d9168c73135fe73c25","tarball":"https://registry.npmjs.org/@attestry/mcp-server/-/mcp-server-1.0.0.tgz","fileCount":35,"unpackedSize":47416,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGazf0UmWIML8IC9etn/0+8cUTlsKh1UKvmA6ggQtUR3AiBL1lhLRKV+qppuoJdLOzv/fgsVn4s130DCecjKmLzosQ=="}]},"_npmUser":{"name":"alerterra","email":"lexwhiting@gmail.com"},"directories":{},"maintainers":[{"name":"alerterra","email":"lexwhiting@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-server_1.0.0_1780178436145_0.5742955230607296"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-30T22:00:36.040Z","1.0.0":"2026-05-30T22:00:36.296Z","modified":"2026-05-30T22:00:36.490Z"},"maintainers":[{"name":"alerterra","email":"lexwhiting@gmail.com"}],"description":"MCP server for Attestry — the cryptographically-verifiable AI compliance platform","homepage":"https://attestry.ai","keywords":["mcp","model-context-protocol","ai-compliance","eu-ai-act","colorado-ai-act","nist-ai-rmf","iso-42001","attestry","compliance","claude"],"author":{"name":"Attestry"},"bugs":{"email":"support@attestry.ai"},"license":"MIT","readme":"# @attestry/mcp-server\n\nMCP (Model Context Protocol) server for [Attestry](https://attestry.ai) — the cryptographically-verifiable AI compliance platform. Lets AI assistants (Claude, Cursor, Windsurf) interact directly with your Attestry compliance data.\n\n## Setup\n\n### 1. Get your API key\n\nCreate an API key in the Attestry app under **Settings → Integrations → API Keys**. The key has full access to the Attestry API — there are no scopes to configure.\n\n### 2. Configure your AI assistant\n\nNo manual install is needed — the configs below launch the server on demand with `npx`. Just set your API key in the `env` block.\n\n#### Claude Desktop\n\nEdit `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\\Claude\\claude_desktop_config.json` (Windows):\n\n```json\n{\n  \"mcpServers\": {\n    \"attestry\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@attestry/mcp-server\"],\n      \"env\": {\n        \"ATTESTRY_API_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n#### Claude Code\n\nAdd to your project's `.mcp.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"attestry\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@attestry/mcp-server\"],\n      \"env\": {\n        \"ATTESTRY_API_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n#### Cursor\n\nEdit `.cursor/mcp.json` in your project root:\n\n```json\n{\n  \"mcpServers\": {\n    \"attestry\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@attestry/mcp-server\"],\n      \"env\": {\n        \"ATTESTRY_API_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n#### Windsurf\n\nEdit `~/.codeium/windsurf/mcp_config.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"attestry\": {\n      \"command\": \"npx\",\n      \"args\": [\"-y\", \"@attestry/mcp-server\"],\n      \"env\": {\n        \"ATTESTRY_API_KEY\": \"your-api-key-here\"\n      }\n    }\n  }\n}\n```\n\n## Environment Variables\n\n| Variable | Required | Default | Description |\n|----------|----------|---------|-------------|\n| `ATTESTRY_API_KEY` | Yes | — | Your Attestry API key (full access) |\n| `ATTESTRY_API_URL` | No | `https://attestry.app` | Attestry API base URL (SaaS control plane). The default is correct for the hosted product; override only for self-hosted/staging. |\n\n## Tools\n\n### `attestry_check_compliance`\n\nCheck an AI system's compliance status against regulatory frameworks.\n\n**Input:**\n- `systemId` (string, required) — UUID of the AI system\n- `frameworks` (string[], optional) — Frameworks to check (e.g., `[\"eu_ai_act\", \"colorado_ai_act\"]`)\n\n**Output:** Pass/fail status, score, compliance issues, active attestation count, last-assessed + checked timestamps, and recommendations.\n\n---\n\n### `attestry_classify_system`\n\nClassify an AI system's risk level across all applicable frameworks.\n\n**Input:**\n- `systemId` (string, required) — UUID of the AI system\n\n**Output:** Overall risk level, per-framework classifications with rationale, applicable frameworks, and Colorado affirmative-defense status.\n\n---\n\n### `attestry_list_systems`\n\nList all registered AI systems for your organization.\n\n**Input:** None\n\n**Output:** Total count plus, for each system: ID, name, status, overall risk level, applicable frameworks, intended use, and deployment geography.\n\n---\n\n### `attestry_get_assessment`\n\nGet the latest compliance assessment summary for an AI system.\n\n**Input:**\n- `systemId` (string, required) — UUID of the AI system\n\n**Output:** Compliance status, score, framework coverage (applicable / assessed / percentage), active attestations, last-assessed timestamp, and recommendations.\n\n---\n\n### `attestry_list_changes`\n\nGet recent regulatory changes affecting AI compliance.\n\n**Input:**\n- `severity` (string, optional) — Filter: `critical`, `high`, `medium`, `low`\n- `framework` (string, optional) — Filter by framework\n- `limit` (number, optional) — Number of results (default: 10, max: 50)\n\n**Output:** Regulatory changes with titles, summaries, framework, severity, status, published + effective dates, and source URLs.\n\n---\n\n### `attestry_generate_document`\n\nGenerate a compliance document for an AI system.\n\n**Input:**\n- `systemId` (string, required) — UUID of the AI system\n- `docType` (string, required) — One of:\n  - `eu_technical_documentation` — EU AI Act Article 11\n  - `colorado_impact_assessment` — SB 24-205\n  - `risk_management_plan` — NIST AI RMF\n  - `model_card` — Transparency documentation\n  - `post_market_monitoring_plan` — EU AI Act Article 72\n  - `consumer_disclosure` — Colorado consumer notice\n  - `nist_ai_rmf_profile` — NIST framework profile\n  - `custom_framework_report` — Custom framework\n- `assessmentId` (string, optional) — Include assessment data\n- `useAI` (boolean, optional) — Use AI for narrative generation (default `false`; consumes AI credits)\n\n**Output:** Document ID, type, framework, generation timestamp, and a signed download URL + token (expires in ~72 hours).\n\n## Resources\n\n| URI | Description |\n|-----|-------------|\n| `attestry://systems` | List of AI systems with risk classifications |\n| `attestry://changes` | Recent regulatory changes |\n| `attestry://status` | Compliance dashboard summary |\n\n## Example Prompts\n\nOnce configured, you can ask your AI assistant:\n\n- \"Check the compliance status of my AI system\"\n- \"What's the risk classification for system X?\"\n- \"Show me recent regulatory changes for the EU AI Act\"\n- \"Generate a Colorado Impact Assessment for my hiring AI\"\n- \"List all my registered AI systems\"\n- \"What's my overall compliance status?\"\n\n## Supported Frameworks\n\n- **EU AI Act** — Risk classification, technical documentation, post-market monitoring\n- **Colorado AI Act (SB 24-205)** — Impact assessments, consumer disclosures, affirmative defense\n- **NIST AI RMF** — Risk management profiles, governance documentation\n- **ISO 42001** — AI management system certification readiness\n\n## Development\n\nClone the repository, then from `mcp-server/`:\n\n```bash\nnpm install\nnpm run dev    # Watch mode\nnpm run build  # Production build\nnpm start      # Run the server\n```\n\n## License\n\nMIT © Attestry\n","readmeFilename":"README.md","_rev":"1-f655148a991aaae1463cc6581e5d7642"}